Security and Compliance

Controls and posture our regulated customers expect.

REQUORDIT serves financial services, government, and industrial customers with audit and compliance obligations. Our security program is designed to meet the controls those teams already run against their own vendors.

Security & Compliance Certifications

SOC 2 Type 1HIPAA CompliantGDPR — General Data Protection Regulation

Data protection layer

Data protection

Encryption in transit and at rest across hosted services. Customer data is segregated by tenant and accessed under least-privilege principles.

AES-256TLS 1.3Tenant isolation

Infrastructure health

Hosting and infrastructure

Managed Cloud workloads run on hardened, monitored cloud infrastructure with documented backup, recovery, and change management procedures.

SOC 2BackupsChange mgmt

Identity & access

Access control

Role-based access, SSO support, and audit logging for administrative actions. Production access is limited to named personnel with logged sessions.

SSOMFARBACAudit log

Compliance posture

Compliance posture

Aligned to the controls expected by our regulated customers in financial services, government, and industrial sectors, including SOC-type review, NIST alignment, and customer-specific contractual controls.

SOC 2NISTHIPAAGDPR

Incident response

Incident response

Documented incident response plan with defined severity levels, escalation paths, and customer notification commitments contracted at engagement start.

PlaybooksSLANotifications

Vendor & supply chain

Vendor and supply chain

Subprocessors are reviewed before onboarding and re-reviewed on a recurring cadence. We provide a current subprocessor list to customers under NDA on request.

SubprocessorsNDAReview

Documentation

Requesting documentation

Customers and prospective customers can request our current security overview, subprocessor list, and applicable compliance reports under NDA. Reach out and our team will route the request to the practice lead for your environment.